Do not log event id 4688 – A new process has been created

Using Group Policy Editor (gpedit.msc) or Local Security Policy (secpol.msc) Security Settings -> Audit Policy -> Audit Process Tracking or Advanced Audit Policy Configuration -> System Audit Policy -> Detailed Tracking -> Disabled.

Even issuing

auditpol /clear
auditpol /get /category:*

shows Process creation: no auditing

Still have those event id 4688 in Security Log.

Windows 10

4 Reset to default

Know someone who can answer? Share a link to this question via email, Twitter, or Facebook.

Your Answer

Sign up or log in

Sign up using Google Sign up using Facebook Sign up using Email and Password

Post as a guest

By clicking “Post Your Answer”, you agree to our terms of service, privacy policy and cookie policy

You Might Also Like